Digi International PortServer TS, Digi One SP IA

MonitorCVSS 5.9ICS-CERT ICSA-26-188-07Jul 7, 2026
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityHigh
User InteractionNone needed
Summary

Digi International PortServer TS, Digi One SP, Digi One SP IA, and Digi One IA devices contain authentication bypass vulnerabilities (CWE-863) and stored cross-site scripting flaws (CWE-79) in their web interfaces. Successful exploitation allows attackers to bypass authentication restrictions, access configuration resources without proper credentials, extract stored credentials, and inject malicious scripts that execute when authorized users access the interface. The vulnerabilities are rooted in insufficient access controls and inadequate input validation on the web application.

What this means
What could happen
An attacker could bypass authentication on the web interface and gain access to configuration settings, extract stored credentials, or inject malicious scripts that execute on the device. This could lead to unauthorized changes to serial port configurations or complete control over connected industrial equipment.
Who's at risk
Water utilities, electric utilities, and other critical infrastructure operators using Digi remote terminal unit (RTU) servers and serial port management devices for SCADA system monitoring and control. These devices are commonly deployed to provide out-of-band access to PLCs, RTUs, and legacy industrial equipment.
How it could be exploited
An attacker with network access to the web interface (port 80/443) can bypass authentication controls due to insufficient access restrictions and script validation. They can then access sensitive configuration data, steal credentials stored on the device, or inject JavaScript payloads that execute in the web browser of authorized users.
Prerequisites
  • Network access to the web interface (HTTP port 80)
  • No authentication bypass required for initial access to certain resources
  • User interaction required for stored script injection attacks (XSS)
remotely exploitablelow complexityno authentication required for some resourcesaffects configuration interfaces on critical infrastructure devicesallows credential theft
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Public Proof-of-Concept (PoC) on GitHub (2 repositories)
Affected products (4)
4 with fix
ProductAffected VersionsFix Status
PortServer TS<Firmware 2025Fix available
Digi One SP<Firmware 2025Fix available
Digi One SP IA<Firmware 2025Fix available
Digi One IA<Firmware 2025Fix available
Remediation & Mitigation
0/4
Do now
0/3
PortServer TS
HARDENINGFor PortServer TS: Enable HTTPS on the web server to encrypt credentials and prevent man-in-the-middle attacks.
Digi One SP
WORKAROUNDFor Digi One SP, Digi One SP IA, and Digi One IA: Disable the web server if not actively required for configuration.
All products
HARDENINGRestrict firewall access to the web interface to only authorized engineering workstations and VPN connections; block access from untrusted networks.
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

PortServer TS
HOTFIXUpgrade PortServer TS, Digi One SP, Digi One SP IA, and Digi One IA firmware to version 2025 or later when available.
API: /api/v1/advisories/08f86574-2657-4449-ad67-d2a29647e70e

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.